HP TMS zl Module Security Administrator's Guide

4-132
Configuring a VPN on the HP TMS zl Module
Configuring an IPsec Site-to-Site VPN with IKE
9. For Local Gateway on Site 1, specify the IP address or TMS VLAN at which
the other module or modules reach the Site 1 module. You have two
options:
•Select IP Address and type the IP address in the box.
The IP address must be an IP address that is configured on the TMS zl
Module and that the remote module or modules can reach (indicated
by 1 in the example figure).
•Select VLAN and select a VLAN from the list.
Select the VLAN on which the remote module or modules reach the
TMS zl Module (indicated by 1 in the example figure).
10. For Local Gateway on Site 2, follow the same procedure to specify the IP
address or TMS VLAN at which the other module or modules reach the
Site 2 module (indicated by 3 in the example figure).
Note If you have selected two sites for the configuration, the wizard will automat-
ically reverse the settings to create the correct remote gateway settings on
each device. Otherwise, the setting is called Remote Gateway, and you must
configure that device with compatible settings separately.
Note Later you will configure firewall access policies to allow the IKE messages
between the TMS zl Modules.